project-stage-detect
Pass
Audited by Gen Agent Trust Hub on Mar 28, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill performs legitimate file system analysis to determine project status. All activities are confined to the local project environment and match the intended purpose.
- [COMMAND_EXECUTION]: Uses standard utilities such as
Bash,Glob, andGrepfor scanning project structures and counting files. No evidence of shell injection or arbitrary command execution was detected. - [DATA_EXPOSURE]: Accesses project-related files in directories like
design/,src/, andproduction/. It does not target sensitive system locations (e.g.,.ssh,.aws) or environment variables, and lacks network capabilities to exfiltrate data. - [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface for indirect injection as it processes untrusted project files.
- Ingestion points: Analyzes content from files within
design/,src/,production/, andprototypes/using theReadandGreptools. - Boundary markers: Absent; the skill does not explicitly delimit untrusted file content from its own instructions.
- Capability inventory: Uses
Read,Glob,Grep, andBash. It has the ability to write a markdown report to theproduction/directory. - Sanitization: Absent; content is analyzed as-is.
- Mitigation: The risk is significantly reduced by the 'Collaborative Protocol', which forces the agent to ask for user approval before taking any action (such as writing a report) based on its findings.
Audit Metadata